---
title: "Env Linter"
description: "Lint .env text for duplicate keys, invalid names, unquoted spaces, export prefixes, masked secret candidates, and drift against .env.example in your browser."
url: https://findutils.com/developers/env-linter/
category: developers
---

# Env Linter

Lint .env text for duplicate keys, invalid names, unquoted spaces, export prefixes, masked secret candidates, and drift against .env.example in your browser.

**Use this tool:** [Env Linter](https://findutils.com/developers/env-linter/)

## Programmatic access

- REST id `env-linter`: POST https://api.findutils.com/api/tools/env-linter/execute (reference: https://findutils.com/api/env-linter/)
- MCP tool `env_linter` on https://mcp.findutils.com (reference: https://findutils.com/mcp/env-linter/)

## Why lint a .env file

Small mistakes in dotenv files fail at runtime. This page checks duplicate keys, unquoted values with spaces, export prefixes, and key drift. Secret-looking values are masked in the findings. The text is not uploaded to FindUtils. Analytics or ads on the page may still load.

## Env Linting Tips

- Paste .env.example with .env when you need a key drift report.
- Remove duplicate keys even when your current dotenv parser accepts them.
- Quote a value that contains spaces so its intended boundary is clear.
- Treat secret masking as a warning aid, not a complete secret scanner.
- Fix the source file in your editor because this tool does not change pasted text.

## Frequently Asked Questions

### Does this upload secrets?

No. FindUtils runs the lint in your browser and does not upload or store the .env text. Secret-looking values are masked in the result table, but detection is not complete.

### What does it flag?

It flags duplicate keys, invalid lines, invalid names, export prefixes, unquoted spaces, and selected secret candidates. It can also compare keys with an optional .env.example file.

### Is this a parser for every dotenv dialect?

No. FindUtils Env Linter checks common dotenv file shapes. It is not a complete shell parser or a framework-specific configuration loader.

### Can I compare two files?

Yes. Paste .env and the optional .env.example text. The report identifies keys that exist in only one input. To also see which shared keys have different values, compare the two files in [Env Diff](https://findutils.com/developers/env-diff/), and to combine two files into one, use [Env Merge](https://findutils.com/developers/env-merge/).

### Does it change my file?

No. The tool reports issues and displays parsed keys only. Make each correction in your source file and run the lint again.

### Does masking find every secret?

No. It recognizes selected token patterns and secret-like key names. An unrecognized sensitive value can remain visible, so review the input and result carefully.

### What does the .env.example comparison report?

It reports keys that are missing from .env. It also reports keys present in .env but absent from .env.example.

### Are comments and blank lines errors?

No. The linter ignores blank lines and comment lines. Other non-empty lines must use a supported KEY=value shape.

### Does it validate database URLs or API credentials?

No. It checks file shape and selected secret patterns. It does not contact a database or API, and it cannot prove that a credential works.

### Does it support shell scripts?

No. It checks common dotenv files only. Shell expansion, commands, substitutions, and full shell grammar are outside its scope.

## Related Tools

- [Env Diff](https://findutils.com/developers/env-diff/)
- [Env Merge](https://findutils.com/developers/env-merge/)
- [JSON Formatter](https://findutils.com/developers/json-formatter/)
- [JWT Decoder](https://findutils.com/developers/jwt-decoder/)
- [HMAC Generator](https://findutils.com/security/hmac-generator/)
